cstamas commented on issue #1038: URL: https://github.com/apache/maven-enforcer/issues/1038#issuecomment-5816829688
Maven 3.6.3 is pre-COVID (2019), so for sure this cannot be considered as security vulnerability, since, IF this Maven version is used _today_ (FTR, it is 2026), we can clearly assume that given organization uses outdated tools, so maybe their operating systems are from 2019 as well? 😄 Jokes aside, the enforce cares about your project. It enforces they your project directly does not introduce this repository. Maven, by its nature (way of working) provides this behaviour, as it is must exactly in valid cases, like in your reproducer, when valid dependency must come from some other (valid) 3rd party repository. If you fully want to prevent this, fast forward to tools released post-COVID, like 2023 year is, and use Maven 3.9.7 that introduced the `--ignore-transitive-repositories` command line option. When you use this option, the **burden to collect into your POM all required repositories is on you (user)** with all the pros and cons, as during resolution, they are ignored (try it out on your reproducer). For environments you mention (ie org with some policies), I'd recommend this: make sure their POM (or parent POM) contains the "curated" remote repositories, and consistently set `-itr` for example in `.mvn/maven.config`. On more serious places, there are MRMs in place, that not only cache, but also may enforce much more checks and policies. Again, IMHO this falls outside of enforcer (plugin), as plugin cares (and can care) only about your project, but this behaviour is happening at resolver level (much deeper), and can be triggered even by a plugin transitive dependency. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
